---
title: "Hidden Context Exposure"
description: "LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions…"
canonical: https://aigovernanceengineer.com/glossary/hidden-context-exposure
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Hidden Context Exposure

LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions, retrieved policy text and tool schemas [1]. The advice is to assume hidden context is discoverable, keep credentials out of it and never rely on it as a security boundary.

- Developed in: [ch. 23, Prompts as configuration under change control](https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Prompt injection](https://aigovernanceengineer.com/glossary/prompt-injection)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-hidden-context-exposure

## Sources

[1] OWASP GenAI LLM Top 10 2026 (published 3 Aug 2026; LLM01:2026 Prompt Injection, incl. memory persistence; LLM08:2026 Hidden Context Exposure, which replaced System Prompt Leakage: assume hidden context is discoverable, no credentials in it, not a security boundary; final text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
